logo

SHADOW#REACTOR Malware Builds Remcos RAT via Text Files

ID: cb4cb9f8-302f-5f12-bdba-f0dbe4b86686

STIX ID: report--cb4cb9f8-302f-5f12-bdba-f0dbe4b86686

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-15

Date Updated: 2026-04-23

Author: Ddos

...
...

Securonix research identifies SHADOW#REACTOR, a sophisticated loader framework that avoids disk-based artifacts by retrieving fragmented text payloads, reconstructing and decoding them in memory via a .NET Reactor-protected assembly, and using legitimate Windows binaries (wscript.exe, MSBuild.exe) to deploy the Remcos RAT at scale; the campaign appears indiscriminate, financially motivated, and designed to provide initial access for further criminal activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.